The choice follows where the code, the runners and the servers live:
| Registry | Type | Licence or pricing model | Best when |
|---|---|---|---|
| Docker Hub 514 | Hosted | Free tier with pull limits; paid plans | Public images, official bases |
| GitHub Container Registry 29 | Hosted | Free storage and bandwidth today | Code and CI already on GitHub 29 |
| Amazon ECR 24 , Azure 6 ACR, Google Artifact Registry | Hosted | Pay per GB stored and transferred | Servers on that cloud |
| Distribution (registry) | Self-hosted | Apache-2.0 | Local, CI caches, air-gapped labs |
| Harbor 109,941 | Self-hosted | Apache-2.0, CNCF graduated | Teams needing RBAC, scanning, replication |
| Zot | Self-hosted | Apache-2.0 | A small OCI-native registry |
Harbor (https://github.com/goharbor/harbor 29,466 ) (2.15.2) wraps Distribution with projects, role-based access, Trivy 67,732 scanning and replication, at the cost of about ten containers; Zot (https://github.com/project-zot/zot 2,811 ) (2.1.21) is a single binary storing the OCI layout on disk. Also weigh egress (a registry in the servers' region is faster and usually free to pull from), availability (with the registry down, nothing new starts) and trust (who can push, and whether images are scanned and signed: Container Security).